LayerZero Attributes $290 Million Kelp Exploit to North Korea's Lazarus, Citing Kelp's Security Setup
LayerZero has pointed to Kelp's security configuration as the primary reason for the $290 million exploit, stating that the protocol's single-verifier setup, contrary to LayerZero's advice, was the key factor. The attack, attributed to North Korea's Lazarus Group, involved the compromise of two RPC nodes used by LayerZero's verifier, which were then used to deceive the system into confirming a fraudulent transaction. This was achieved by swapping the binary software on these nodes with malicious versions that reported false data to LayerZero's verifier while maintaining accurate data for other systems. To ensure the success of the attack, the perpetrators also launched a distributed denial-of-service (DDoS) attack on uncompromised external RPC nodes, forcing a failover to the compromised nodes. The DDoS, which occurred between 10:20 a.m. and 11:40 a.m. Pacific Time on Saturday, resulted in the release of 116,500 rsETH to the attackers. LayerZero emphasizes that the attack's success was contingent upon Kelp's use of a 1-of-1 verifier configuration, which allowed the poisoning of a single verifier's data feed to forge a valid message. In contrast, a multi-verifier setup with redundancy, as recommended by LayerZero, would have required consensus across several independent verifiers, thereby preventing the attack. LayerZero has confirmed that there was no contagion to other applications on the protocol and has since brought its verifier back online, announcing that it will no longer support applications with single-verifier configurations. The distinction between a protocol-level bug and a configuration failure is significant for how DeFi assesses LayerZero's risk. While a protocol-level bug would have implied that every OFT token was at risk, the fact that the exploit resulted from a targeted infrastructure attack and a single integrator's configuration failure suggests that the protocol functioned as designed. Kelp's decision to operate a 1-of-1 verifier setup, despite explicit recommendations against it, has not been publicly addressed. The Lazarus Group, linked to both the Kelp and Drift Protocol exploits, has drained over $575 million from DeFi in 18 days, demonstrating its ability to adapt its tactics faster than DeFi protocols can strengthen their defenses.